Resources - Blog

Microsoft Is Retiring SMS And Voice Authentication In Favour Of Phishing-Resistant MFA - Will Your Business Be Ready?

Rami Kayyali
August 18, 2026

If SMS and voice disappeared from your sign-in flow tomorrow, would your team even notice? Or would half your users be locked out and your IT department overwhelmed?

That question stops being hypothetical soon. Microsoft has set two dates that change how everyone on Entra ID authenticates, and the direction of travel is towards phishing-resistant MFA by default. This is not a new feature buried in a settings menu you can ignore; it is a change to the default behaviour of the platform, and it arrives with a hard deadline attached. If your organisation still leans on a phone number as its second factor, the clock is already ticking.

What Microsoft Actually Announced and When It Bites

The plan is public and dated. Microsoft is making passkeys the default and retiring voice and SMS MFA, and it is happening in two stages.

From 1 September 2026, Entra ID begins nudging users still relying on SMS or voice MFA to register a passkey at sign-in, and will move to enable phishing-resistant methods as the default over a phased rollout. Nothing breaks yet, but the default shifts. Readers should verify the precise nudge behaviour and rollout schedule against the official Microsoft documentation linked above, as implementation details may be updated before the date arrives.

From 1 February 2027, Microsoft-provided SMS and voice delivery is scheduled to be retired outright .Organisations that configure a customer-managed telecom provider through the Microsoft Security Store (available from 30 October 2026) can keep using SMS and voice beyond that date - but this needs setting up in advance, and most organisations won't bother, which is exactly why passkey migration is the simpler path.  After that date, according to current Microsoft guidance, anyone whose only registered MFA method is a phone number is expected to receive a blocking prompt to register a passkey before they can sign in. No passkey, no access. Confirm the exact mechanism against the official Microsoft documentation as the date approaches, as specifics may be refined.

That second date is the one that matters. It is not a recommendation or a warning banner; it is a gate.

Why Microsoft Is Doing This Now

SMS and voice have always been the weakest links in the MFA chain. They were better than a password alone, which is why they became so widespread, but attackers caught up years ago.

A one-time code sent to a phone can be intercepted by adversary-in-the-middle (AITM) attacks, redirected through a SIM-swap, or simply phished by a convincing fake login page that relays the input data in real time. The whole method depends on a shared secret travelling across a channel you do not control. That is exactly the weakness modern phishing kits are built to exploit.

Passkeys close that gap because they are phishing-resistant MFA by design. There is no code to read out, no identifying data to hand over, and nothing an attacker can capture and relay. For an organisation trying to stop credential phishing at the point of sign-in, retiring the weakest method is the logical move. Microsoft is simply making that decision for the whole platform rather than leaving it up to the individual.

What Qualifies as Phishing-Resistant MFA?

Phishing-resistant MFA is authentication that cannot be tricked into handing a valid credential to an attacker, even when the user is fooled. Three properties define it:

  • The credential is cryptographically bound to the legitimate website or service, so it will not work against a lookalike domain.
  • It resists interception and replay, because there is no reusable code passing through a channel an attacker can sit on. 
  • There is no shared secret to phish in the first place. 

A code texted to a phone fails all three tests. A FIDO2 passkey passes them, which is why regulators and platform vendors increasingly treat it as the baseline rather than the aspiration.

Are Passkeys Multi-Factor Authentication?

Yes: a passkey combines two factors in a single action. There is possession - the device or credential store that holds the private key material, whether that is a hardware security key, a phone, or a synced passkey in a password manager - and there is a local factor - the biometric or PIN that unlocks it. Both have to be present for authentication to succeed, which is the definition of multi-factor. 

The difference from older setups is that passwordless authentication removes the password entirely rather than bolting a second factor onto it. You are not entering a password and then confirming a code. You are proving possession of the key and unlocking it locally, in one step, with no unsecured credential exchange anywhere in the flow.

Are Passkeys Considered Phishing-Resistant?

Yes, they are, thanks to the FIDO2 standard they are built upon. A passkey is origin-bound, meaning the credential is tied to the exact domain it was registered against. When a user lands on a spoofed site, the passkey simply will not respond, because the origin does not match. There is no moment where a human decision can be manipulated into approving the wrong thing.

For anyone deploying FIDO2 passkeys enterprise-wide, that origin-binding is the whole point. It moves the security guarantee out of the user's judgement and into cryptography that a phishing page cannot satisfy.

What Being Ready Actually Looks Like

The February cut-off requires knowing where your organisation stands, and making a deliberate choice in good time rather than inheriting one.

Start with three questions:

  • Which users are still on SMS or voice? You cannot plan a migration you cannot see. The users most exposed are often the ones with the most access. Not sure how many of your users are still on phone-based MFA? A security posture assessment gives you a clear picture of where your organisation stands before the February cut-off, so you migrate on your terms rather than Microsoft's.
  • Managed rollout or default drift? You can run a controlled deployment on your own timeline, or you can let Microsoft's auto-enrolment carry your users across from September onwards. The first gives you control over training, support, and edge cases. The second leaves your help desk to absorb whatever surprises land at sign-in.
  • Which passkey type for which user? Device-bound passkeys tied to a single laptop or phone are fine for many staff. They are a poor fit for admins, executives, and remote workers who move across devices and cannot afford to be locked out of one.

That last point is where the choice between device-bound and hardware-backed passkeys stops being academic.

Where Yubico Fits

Hardware-backed FIDO2 keys give you phishing-resistant authentication that is not tied to a single device. That portability is the practical advantage over device-bound passkeys, and it matters most in the situations where device-bound options simply do not work.

Think about shared workstations where no single device belongs to one person. Think about contractors who need strong authentication without being enrolled into your full device estate. Think about regulated environments where a hardware token offers a streamlined option since device-bound passkeys are impractical to govern. In each case, a small physical key travels with the person, not the hardware.

This is where Yubico enters the picture. A YubiKey provides a portable, hardware-backed credential that works across the devices a user actually touches, which is exactly what admins, executives, and remote staff need heading into the retirement dates. 

For a full breakdown of the mechanism, Yubico's secure and versatile YubiKey solution covers exactly how YubiKey phishing-resistant MFA works in practice.

The Next Step

The Microsoft dates are fixed, but what is not fixed is whether your organisation reaches them well prepared or scrambling. The gap between those two outcomes is visibility: knowing which users, which methods, and which risks sit in your tenant right now.

A security posture assessment from The Kernel tells you exactly that. 

Get in touch to find out where your organisation stands before the February cut-off, and turn a platform change you did not choose into a migration you control.

Frequently Asked Questions

When is Microsoft retiring SMS and voice MFA? 

In two stages. From 1 September 2026, Entra ID begins nudging users still on SMS or voice to register a passkey, with phishing-resistant methods becoming the default over a phased rollout. From 1 February 2027, Microsoft-provided SMS and voice delivery is scheduled to be retired outright.

Will my users be locked out if they only use phone-based MFA? 

After 1 February 2027, users whose only MFA method is a phone number will hit a blocking prompt requiring passkey registration before they can sign in. Microsoft doesn't officially call this a 'lockout,' but in practice, no passkey means no access - registering an alternative method beforehand avoids the disruption.

What is the difference between device-bound passkeys and hardware security keys? 

A device-bound passkey lives on one specific device, such as a laptop or phone. A hardware security key like a YubiKey is a portable credential that works across multiple devices, with a versatility that suits admins, executives, remote workers, and shared workstations.

Do we need to act before 1 September 2026 or 1 February 2027? 

Both dates matter. September 2026 is when default behaviour starts changing. February 2027 is the hard retirement when phone-only users get blocked. Acting before September lets you run a managed rollout instead of inheriting Microsoft's automatic one.

Is passwordless authentication suitable for regulated environments? 

Yes. Hardware-backed FIDO2 keys provide phishing-resistant, auditable authentication that often fits regulated environments better than device-bound passkeys, because the credential is portable and independent of any single managed device.

About the author
Rami Kayyali
Chief Technology Officer, The Kernel
Rami Kayyali is Chief Technology Officer at The Kernel. He works with cybersecurity vendors, channel partners and organisations on the evaluation, architecture and deployment of identity, authentication and security technologies across the Middle East and Africa. His areas of expertise include identity and access management, FIDO2 and phishing-resistant authentication, public key infrastructure, and cybersecurity solution architecture.
Identity and access management, FIDO2 and phishing-resistant authentication, public key infrastructure, and cybersecurity solution architecture.

Want these in your inbox?

We publish practical, vendor-neutral writing on identity, authentication, and security operations in the region. No spam, no hard sell.

First name
Last name
Email
Thank you for subscribe.
Oops! Something went wrong while submitting the form.